# Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploited

> SPIP versions before 4.4.21 contain a universal, pre-authentication remote code execution vulnerability (CVE-2026-77806, CVSS 9.8) in which the analyse_resultat_skel() template function mishandles an attacker-supplied X-Spip-Filtre HTTP header, letting an unauthenticated attacker chain PHP filter functions (e.g. intval|_request|system) to execute arbitrary OS commands. The flaw is not mitigated by SPIP's built-in security screen and CERT-FR, SPIP, and multiple vulnerability trackers confirm exploitation attempts in the wild during August 2026; a public Metasploit module was merged 2026-08-24.

- **Published:** 2026-08-29T00:00:00Z
- **Last reviewed:** 2026-08-29T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2221
- **ID:** TL-2026-2221
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-77806, CVE-2026-77647

## Description

SPIP is a widely deployed open-source French CMS used heavily by government, media, and nonprofit sites. On 2026-08-17, SPIP shipped 4.4.20 as an emergency fix for CVE-2026-77647 — a code-injection flaw caused by incorrect identification of <?php blocks and var_export()'s mishandling of a leading '<' character, also reported anonymously via ANSSI and also exploited in the wild before 4.4.20. That patch proved incomplete: on 2026-08-20 SPIP released 4.4.21 to fix a second, related pre-authentication RCE, CVE-2026-77806.

CVE-2026-77806's root cause is a function-call injection flaw in analyse_resultat_skel(), the core SPIP template-rendering function. When a compiled template body contains a `<?php header("X-Spip-Filtre: ..."); ?>` marker, the colon-delimited function names found there are invoked as a chain of PHP filters against the reachable output — but SPIP fails to prevent an attacker from supplying that marker's value directly via the real HTTP request's X-Spip-Filtre header, and from steering user-controlled text into the compiled template body in the first place. The documented path to that compiled body is the forum-preview feature: an unauthenticated visitor's submission to the public forum "texte" field is rendered through the vulnerable skeleton compiler (reachable via endpoints such as ecrire/?exec=forum), giving an attacker a route to the sink without any account or session. The publicly available Metasploit module (multi/http/spip_x_spip_filtre_rce, rapid7/metasploit-framework PR #21790, authored by Julien Voisin/jvoisin, merged 2026-08-24) demonstrates the exploitation primitive: the filter chain `intval|_request|system` first collapses the response body to the string "0" via intval(), then _request() re-reads a POST parameter literally named "0" containing an attacker-supplied OS command string, which system() then executes — yielding unauthenticated, unattended remote code execution with a single crafted HTTP request. The module supports delivery via GET parameter injection, a forum POST to the texte field, or newline injection to smuggle the header value into the request, and was validated against SPIP 4.4.19 and 4.4.20.

Critically, both the CERT-FR advisory and the SPIP vendor bulletin state that this flaw is NOT caught by SPIP's built-in "security screen" (écran de sécurité) — the CMS's dedicated input-filtering defense layer that normally screens malicious-looking public-area submissions — meaning sites relying solely on that built-in protection remain exposed even if otherwise hardened. No CVSS score was published at initial CERT-FR/vendor disclosure, but subsequent NVD/vulnerability-database entries score it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) against CPE cpe:2.3:a:spip:spip — network-exploitable, low complexity, no privileges or user interaction required, full compromise of confidentiality, integrity, and availability. EPSS places it at roughly the 90th percentile (~4.2% 30-day exploitation probability), and an independent SSVC assessment rates the exploitation method as "Automatable" with "total" technical impact, consistent with the availability of a scriptable, unauthenticated, single-request exploit. As of this research, CVE-2026-77806 has not yet been added to the CISA Known Exploited Vulnerabilities catalog despite confirmed in-the-wild exploitation.

Remediation is a straightforward version upgrade: SPIP 4.4.21 (or later), delivered via spip_loader 7.0.0 or manual download from get.spip.net. Where immediate patching is not feasible, defenders should block or strip inbound X-Spip-Filtre headers at a WAF or reverse proxy in front of any public-facing SPIP deployment, and monitor forum-submission endpoints for anomalous PHP-filter-name strings, since the vendor's own built-in filtering does not stop this vector.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1590 Gather Victim Network Information
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1071 Application Layer Protocol

## Sources

- [CERTFR-2026-AVI-1063 — Vulnérabilité dans SPIP](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1063/)
- [Mise à jour critique de sécurité : sortie de SPIP 4.4.21](https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-21.html)
- [CVE-2026-77806 Record](https://www.cve.org/CVERecord?id=CVE-2026-77806)
- [CVE-2026-77806 Detail - NVD - NIST](https://nvd.nist.gov/vuln/detail/CVE-2026-77806)
- [CVE-2026-77806 – Unauthenticated Remote Code Execution – SPIP before 4.4.21](https://www.ionix.io/threat-center/cve-2026-77806/)
- [CVE-2026-77806: SPIP: SPIP before 4.4.21 allows unauthenticated RCE](https://www.rapid7.com/db/vulnerabilities/cve-2026-77806/)
- [CVE-2026-77806: SPIP Code Injection (CVSS 9.8) — Fix & Details](https://www.strix.ai/cve/CVE-2026-77806)
- [CVE-2026-77806 | INCIBE-CERT | INCIBE](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-77806)
- [Critical SPIP Pre-Auth RCE Exploited in the Wild and Added to Metasploit](https://mallory.ai/stories/01a021a8-9ead-79f0-8fca-50b1b30b1046)
- [Metasploit module multi/http/spip_x_spip_filtre_rce (PR #21790)](https://github.com/rapid7/metasploit-framework/pull/21790)
- [CVE-2026-77806 - Vulnerability Details - OpenCVE](https://opencve.alliance.unm.edu/cve/CVE-2026-77806)
- [SPIP Code Injection Vulnerability Allows Unauthenticated Remote Code Execution (CVE-2026-77806)](https://techjacksolutions.com/scc-intel/spip-code-injection-vulnerability-allows-unauthenticated-remote-code-execution-cve-2026-77806/)
- [CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated RCE](https://x.com/CVEnew/status/2090573598012363077)
- [SPIP Unauthenticated RCE (CVE-2026-77647)](https://www.thehackerwire.com/spip-unauthenticated-rce-cve-2026-77647/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2221
